LabReach
LabReach is an OrderComms solution that provides a web-based portal enabling users to order diagnostic tests directly into laboratory LIMS systems across the Labgnostic network. Test results are automatically streamed back to the portal, with configurable email notification options to keep users informed of result availability.
Features
- Web-based portal accessible from any modern browser without software installation
- Direct integration with laboratory LIMS systems across the Labgnostic network
- Real-time test ordering workflow from portal to laboratory systems
- Automated results streaming from laboratories back to the portal
- Configurable email notification system for result availability alerts
- Secure data transmission between portal, laboratories, and users
- User authentication and access control mechanisms
- Audit trail of orders and result delivery
Benefits
- Streamlines diagnostic test ordering, reducing administrative burden
- Eliminates manual data entry errors through LIMS integration
- Faster test result turnaround through automated delivery
- Centralised visibility of orders and results
- Automated notifications for timely result awareness
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 0 3 3 8 0 7 1 4 3 5 8 8 0 4
Contact
X - LAB LIMITED
Commercial Department
Telephone: 07787656851
Email: enquiries@x-labsystems.co.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- N/A
- System requirements
- N/A - we cater for the buyers requirements.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Online ticketing support is provided 9:00 and 17:30 Monday to Friday, excluding Bank holidays. Within these hours the tickets are responded to as follows:
1) Urgent severity - Before the start of the next Business Day;
2) High severity - Before the end of the next Business Day;
3) Medium - 2 Business Days;
4) Low - 3 Business Days - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
-
We provide one standard support level for the LabReach service. This support model applies to all customers equally and is designed to ensure consistent service quality, transparency, and fair use. Support, maintenance, and general software upgrades are included as part of the contracted service.
Support includes:
- Access to a service desk during Normal Business Hours
- Incident management, service requests, and change requests handled in line with ITIL principles
- Defined incident severity levels with documented target resolution times
- Planned maintenance management
- Access to out-of-hours third-line engineering support triggered via automated monitoring (no customer-initiated service desk outside Normal Business Hours).
Customers are provided with a named Account Manager, who acts as the primary commercial and service liaison. This role supports onboarding coordination, service reviews, and future service expansion planning. Technical support is delivered via the service desk and specialist engineering teams as required - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- X-Lab prides itself on excellent customer service with each of our LabReach customers assigned a dedicated Account Manager. The Account Management team is an integral part of the organisation and works closely with the Onboarding and Support team as part of the wider Customer Success function. The Account Managers work closely with the Sales team and are introduced to new LabReach customers during the sales process. Prior to customers' onboarding to the LabReach service, we ensure a contract is agreed and that all organisations joining the network comply with information governance (in the form of a Data Protection Agreement). The Account Manager will work closely with the customer to maintain engagement, agree a utilisation plan, deal with any escalations, communicate service developments, and continually review the customer experience. We provide a welcome pack containing a high-level overview of what to expect during the LabReach onboarding process (including supporting documentation, prerequisites, required stakeholders, key milestones, and a bespoke onboarding plan). Training and support are offered online however there is scope for training to be delivered onsite. Testing scripts are provided to the customer to validate testing ahead of sign off and cutover into production.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- Other
- Other documentation formats
-
- Word
- Excel
- End-of-contract data extraction
- We don't explicitly extract/remove data when a contract ends. We have a Retention Policy which is available on request. Data is removed from the production system after 4 months by default and will be removed from the archive after a further 2 years. Customers can reduce their retention period for production to a shorter period (we recommend no less than ~1 month, but this could be shorter if required). Upon request from an exiting customer a final data extract can be provided. This is a complex process as we would need to obtain agreement from all third party organisations that hold data sharing agreements with the off-boarding customer.
- End-of-contract process
- LabReach customers usually renew their contract at the end of the subscription term. Should a customer decide to end the contract, the termination terms form part of the contractual documentation. The dedicated Account Manager would work with the customer to ensure any outstanding invoices have been paid and would facilitate an off-boarding plan with the relevant teams. The tasks carried out by the X-Lab team include the deletion of the connection profiles, the decommissioning of the Customer VPN and the removal of web access configuration. The team would be required to wait until the archive period elapses and delete the laboratories. End users would need to be removed from the Service desk and CRM system. Users would also need removing from any service communications. The customers would be expected to liaise with other LabReach/Labgnostic partners to communicate and manage the process, although the team at X-Lab could assist and advise where necessary.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding/Offboarding documents are accessible for customers to read in PDF format. If a document is shared requesting information or for collaboration documents are shared as ODF. Documents can also be shared in HTML format. All of our document formats are accessible across all devices including documents containing logos, images, and charts, and can be printed or stored by recipients.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
LabReach is accessed through a web-based portal using any supported modern browser, with no client-side software required.
Laboratory Connectivity:
LabReach uses the Labgnostic platform for LIMS integration:
Pre-built interfaces for common LIMS systems using vendor HL7 specifications
LIMS-agnostic specification for custom development where vendor modules unavailable
User Setup:
Existing Labgnostic customers: Use existing LIMS interface configuration
New laboratories: Configure LIMS interface as a performing laboratory
Laboratory administrators use a separate web interface for configuration and user management. - Accessibility standards
- None or don’t know
- Description of accessibility
-
Current Accessibility Approach:
LabReach is built using modern web development practices and industry-standard design libraries that include accessibility features such as keyboard navigation, ARIA attributes, and semantic HTML elements.
Accessibility Features:
Keyboard navigation support throughout the application
Semantic HTML structure for screen reader compatibility
Responsive design adapting to different viewport sizes and devices
Clear visual contrast and readable typography
Compliance Status:
We have not conducted formal WCAG 2.1 compliance testing or accessibility audits at this time. Organisations with specific accessibility requirements should contact us to discuss their needs and evaluate suitability. - Accessibility testing
- None.
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- LabReach is built to scale horizontally and vertically making best use of available managed cloud services. Given the nature of the service providing a network of customers together, no guarantee can be made that an abnormally high load from one customer would not affect another.
Analytics
- Service usage metrics
- Yes
- Metrics types
- On request we can provide transaction volumes for each customer, and can provide more detailed analysis (e.g. turnaround times or transaction volumes segmented by test type and partner lab) on request. This would require work from Engineers to provide.
- Reporting types
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
LabReach does not currently provide a self-service data export function within the web application.
Customers requiring data exports should contact their Account Manager or the Support team. Upon request, we can provide data exports in JSON format containing the customer's order and result data.
Export requests are processed on a case-by-case basis to ensure data security and that only authorised personnel receive access to their organisation's information. - Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON
- HL7
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- We aim to ensure that the service is available throughout the Subscription Term for 99.7% of the time. There is currently no mechanism for refunds.
- Approach to resilience
- We use Azure's cloud native redundancy and resilience tooling to ensure our platform is spread over multiple data centres and regions within the UK.
- Outage reporting
- Update banners via the service desk and email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Public key authentication (including by TLS client certificate)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Azure AD group membership with conditional access and MFA.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Currently under going certification for ISO 27001.
- Information security policies and processes
- We employ a suite of ~20 information security policies and have built our ISO27001 ISMS policies as part of phase 1 of our audit.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We ensure that security requirements are captured as far left in the SDLC as possible to ensure we have resources to appropriately remediate. All changes are developed using pair programming, and scanned for static code analysis including infrastructure as code static analysis (policy-as-code)
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerabilities identification is done by our vulnerability management tool and reported back every 6 hours. Vulnerabilities are then logged automatically as tickets for the respective team to remediate within our SLAs, with reporting on adherence to SLAs fed up to senior management.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Logging from endpoints, IaaS , PaaS, SaaS tools are ingested by our SIEM and monitored by our SOC on a 24/7 basis with proactive threat hunting activities conducted monthly.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Our incident management approach is holistic as part of our risk management and BC/DR management approach. All suspected or confirmed security incidents are reported to the GRC team & SLT who triage and follow the predefined playbooks for various common incidents. Any live incidents have a PIR conducted with the Lessons Learned captured and remediated within SLAs. Incident Reports are provided to the customer within 48 hours of closure of the incident.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Scottish Wide Area Network (SWAN)
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 3%
- Between £500,001 and £1,000,000
- 6%
- Between £1,000,001 and £2,500,000
- 9%
- Between £2,500,001 and £5,000,000
- 12%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E940d951-581e-4e45-9cfd-61a86de643d4
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- F16f8b35-62c2-4efd-9490-bdf7ea61050e
- Other security certifications
- Yes
- Any other security certifications
- Data Security and Protection Toolkit
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-